CVE-2026-56744: CWE-1288: Improper Validation of Consistency within Input in bsv-blockchain @bsv/wallet-toolbox
A vulnerability in the @bsv/wallet-toolbox packages allows a malicious or compromised remote storage provider to substitute or inject transaction outputs without verification. This causes the wallet to sign and broadcast transactions redirecting funds while the user interface displays the intended recipient. Versions from 1.1.47 through 2.3.3 of @bsv/wallet-toolbox and @bsv/wallet-toolbox-client, and from 1.3.21 through 2.3.3 of @bsv/wallet-toolbox-mobile are affected. The issue is fixed in version 2.4.0. Users unable to upgrade should avoid remote StorageClient providers or verify outputs independently before signing.
AI Analysis
Technical Summary
@bsv/wallet-toolbox and related client packages suffer from improper validation of consistency within input (CWE-1288). Specifically, transactions created via a remote StorageClient trust output locking scripts returned by the storage provider without verifying they match the requested outputs. This allows a malicious or compromised storage provider to substitute recipient scripts or add outputs, causing unauthorized fund redirection while the UI shows the expected recipient. The vulnerability affects stable versions >=1.1.47 <2.4.0 for @bsv/wallet-toolbox and @bsv/wallet-toolbox-client, and >=1.3.21 <2.4.0 for @bsv/wallet-toolbox-mobile. The issue is patched in version 2.4.0.
Potential Impact
An attacker controlling or compromising the remote storage provider can cause the wallet to sign and broadcast transactions that redirect funds to unintended recipients without the user's knowledge. This leads to potential financial loss as the user interface continues to display the intended recipient, misleading users into approving malicious transactions.
Mitigation Recommendations
A fix is available in version 2.4.0 of all affected packages. Users should upgrade to this version to remediate the vulnerability. Applications unable to upgrade should avoid using remote StorageClient providers, use local storage instead, or independently verify every transaction output's locking script and value against the original request before signing to prevent unauthorized fund redirection.
CVE-2026-56744: CWE-1288: Improper Validation of Consistency within Input in bsv-blockchain @bsv/wallet-toolbox
Description
A vulnerability in the @bsv/wallet-toolbox packages allows a malicious or compromised remote storage provider to substitute or inject transaction outputs without verification. This causes the wallet to sign and broadcast transactions redirecting funds while the user interface displays the intended recipient. Versions from 1.1.47 through 2.3.3 of @bsv/wallet-toolbox and @bsv/wallet-toolbox-client, and from 1.3.21 through 2.3.3 of @bsv/wallet-toolbox-mobile are affected. The issue is fixed in version 2.4.0. Users unable to upgrade should avoid remote StorageClient providers or verify outputs independently before signing.
CVSS v4.0
Score 8.7high
Affected software
bsv-blockchain
@bsv/wallet-toolbox
bsv-blockchain
@bsv/wallet-toolbox-client
bsv-blockchain
@bsv/wallet-toolbox-mobile
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
@bsv/wallet-toolbox and related client packages suffer from improper validation of consistency within input (CWE-1288). Specifically, transactions created via a remote StorageClient trust output locking scripts returned by the storage provider without verifying they match the requested outputs. This allows a malicious or compromised storage provider to substitute recipient scripts or add outputs, causing unauthorized fund redirection while the UI shows the expected recipient. The vulnerability affects stable versions >=1.1.47 <2.4.0 for @bsv/wallet-toolbox and @bsv/wallet-toolbox-client, and >=1.3.21 <2.4.0 for @bsv/wallet-toolbox-mobile. The issue is patched in version 2.4.0.
Potential Impact
An attacker controlling or compromising the remote storage provider can cause the wallet to sign and broadcast transactions that redirect funds to unintended recipients without the user's knowledge. This leads to potential financial loss as the user interface continues to display the intended recipient, misleading users into approving malicious transactions.
Mitigation Recommendations
A fix is available in version 2.4.0 of all affected packages. Users should upgrade to this version to remediate the vulnerability. Applications unable to upgrade should avoid using remote StorageClient providers, use local storage instead, or independently verify every transaction output's locking script and value against the original request before signing to prevent unauthorized fund redirection.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-22T19:17:28.959Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab557d2f7a7c5410694c2cf
Added to database: 09/24/2026, 17:03:14 UTC
Last enriched: 09/24/2026, 17:17:43 UTC
Last updated: 09/24/2026, 17:43:59 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.